CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton-Jto a version that resolves this vulnerability.Fixed in 0.35.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66257?
CVE-2026-66257 has a risk score of 35, indicating a moderate severity level.
How do I fix CVE-2026-66257?
To mitigate CVE-2026-66257, users should upgrade Apache Qpid Proton-J to version 0.35.0 or higher.
What kind of attack does CVE-2026-66257 allow?
CVE-2026-66257 allows an attacker to exploit unbounded symbol value caching to cause resource exhaustion and lead to denial of service.
Which versions of Apache Qpid Proton-J are affected by CVE-2026-66257?
CVE-2026-66257 affects Apache Qpid Proton-J versions up to and including 0.34.1.
Is there a workaround for CVE-2026-66257 if I cannot upgrade?
There is no documented workaround for CVE-2026-66257 other than upgrading to the fixed version.